• bitcoinBitcoin (BTC) $ 105,776.00
  • ethereumEthereum (ETH) $ 3,795.34
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 1,065.34
  • xrpXRP (XRP) $ 2.30
  • solanaSolana (SOL) $ 181.73
  • usd-coinUSDC (USDC) $ 0.999818
  • staked-etherLido Staked Ether (STETH) $ 3,793.38
  • tronTRON (TRX) $ 0.310027
  • dogecoinDogecoin (DOGE) $ 0.183625
  • cardanoCardano (ADA) $ 0.619458
  • wrapped-stethWrapped stETH (WSTETH) $ 4,621.37
  • figure-helocFigure Heloc (FIGR_HELOC) $ 1.04
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 106,027.00
  • wrapped-beacon-ethWrapped Beacon ETH (WBETH) $ 4,101.79
  • ethena-usdeEthena USDe (USDE) $ 0.999683
  • chainlinkChainlink (LINK) $ 16.60
  • wrapped-eethWrapped eETH (WEETH) $ 4,103.53
  • stellarStellar (XLM) $ 0.303758
  • hyperliquidHyperliquid (HYPE) $ 35.56
  • bitcoin-cashBitcoin Cash (BCH) $ 465.31
  • binance-bridged-usdt-bnb-smart-chainBinance Bridged USDT (BNB Smart Chain) (BSC-USD) $ 0.999525
  • wethWETH (WETH) $ 3,804.47
  • suiSui (SUI) $ 2.41
  • leo-tokenLEO Token (LEO) $ 9.39
  • avalanche-2Avalanche (AVAX) $ 19.87
  • usdsUSDS (USDS) $ 1.00
  • usdt0USDT0 (USDT0) $ 1.00
  • coinbase-wrapped-btcCoinbase Wrapped BTC (CBBTC) $ 105,968.00
  • hedera-hashgraphHedera (HBAR) $ 0.163177
  • litecoinLitecoin (LTC) $ 88.19
  • whitebitWhiteBIT Coin (WBT) $ 40.50
  • shiba-inuShiba Inu (SHIB) $ 0.000010
  • ethena-staked-usdeEthena Staked USDe (SUSDE) $ 1.20
  • moneroMonero (XMR) $ 293.05
  • the-open-networkToncoin (TON) $ 2.13
  • mantleMantle (MNT) $ 1.62
  • crypto-com-chainCronos (CRO) $ 0.141803
  • daiDai (DAI) $ 1.00
  • polkadotPolkadot (DOT) $ 2.92
  • uniswapUniswap (UNI) $ 6.12
  • bittensorBittensor (TAO) $ 373.48
  • world-liberty-financialWorld Liberty Financial (WLFI) $ 0.128922
  • chainopera-aiChainOpera AI (COAI) $ 17.88
  • okbOKB (OKB) $ 163.17
  • zcashZcash (ZEC) $ 208.18
  • memecoreMemeCore (M) $ 1.93
  • aaveAave (AAVE) $ 210.85
  • bitget-tokenBitget Token (BGB) $ 4.51
  • ethenaEthena (ENA) $ 0.429172
  • blackrock-usd-institutional-digital-liquidity-fundBlackRock USD Institutional Digital Liquidity Fund (BUIDL) $ 1.00
  • pepePepe (PEPE) $ 0.000007
  • usd1-wlfiUSD1 (USD1) $ 0.999329
  • nearNEAR Protocol (NEAR) $ 2.17
  • paypal-usdPayPal USD (PYUSD) $ 1.00
  • jito-staked-solJito Staked SOL (JITOSOL) $ 224.64
  • susdssUSDS (SUSDS) $ 1.07
  • c1usdCurrency One USD (C1USD) $ 1.00
  • ethereum-classicEthereum Classic (ETC) $ 15.34
  • binance-peg-wethBinance-Peg WETH (WETH) $ 3,795.76
  • falcon-financeFalcon USD (USDF) $ 0.995730
  • aptosAptos (APT) $ 3.12
  • ondo-financeOndo (ONDO) $ 0.703909
  • aster-2Aster (ASTER) $ 1.08
  • jupiter-perpetuals-liquidity-provider-tokenJupiter Perpetuals Liquidity Provider Token (JLP) $ 5.30
  • polygon-ecosystem-tokenPOL (ex-MATIC) (POL) $ 0.184334
  • worldcoin-wldWorldcoin (WLD) $ 0.867665
  • story-2Story (IP) $ 5.84
  • htx-daoHTX DAO (HTX) $ 0.000002
  • usdtbUSDtb (USDTB) $ 1.00
  • gatechain-tokenGate (GT) $ 15.39
  • kucoin-sharesKuCoin (KCS) $ 13.92
  • binance-staked-solBinance Staked SOL (BNSOL) $ 195.84
  • bfusdBFUSD (BFUSD) $ 0.999772
  • rocket-pool-ethRocket Pool ETH (RETH) $ 4,351.21
  • hash-2Provenance Blockchain (HASH) $ 0.033472
  • pi-networkPi Network (PI) $ 0.201584
  • internet-computerInternet Computer (ICP) $ 3.05
  • arbitrumArbitrum (ARB) $ 0.303079
  • tether-goldTether Gold (XAUT) $ 4,304.39
  • algorandAlgorand (ALGO) $ 0.178104
  • cosmosCosmos Hub (ATOM) $ 3.17
  • kelp-dao-restaked-ethKelp DAO Restaked ETH (RSETH) $ 4,008.50
  • vechainVeChain (VET) $ 0.017202
  • stakewise-v3-osethStakeWise Staked ETH (OSETH) $ 4,011.80
  • wbnbWrapped BNB (WBNB) $ 1,067.05
  • skySky (SKY) $ 0.060118
  • kaspaKaspa (KAS) $ 0.052322
  • kinetic-staked-hypeKinetiq Staked HYPE (KHYPE) $ 35.31
  • pax-goldPAX Gold (PAXG) $ 4,333.99
  • liquid-staked-ethereumLiquid Staked ETH (LSETH) $ 4,092.38
  • pudgy-penguinsPudgy Penguins (PENGU) $ 0.021200
  • lombard-staked-btcLombard Staked BTC (LBTC) $ 105,880.00
  • flare-networksFlare (FLR) $ 0.016731
  • render-tokenRender (RENDER) $ 2.45
  • syrupusdcSyrup USDC (SYRUPUSDC) $ 1.13
  • sei-networkSei (SEI) $ 0.194438
  • renzo-restaked-ethRenzo Restaked ETH (EZETH) $ 4,028.64
  • pump-funPump.fun (PUMP) $ 0.003423
  • nexoNEXO (NEXO) $ 1.17
  • official-trumpOfficial Trump (TRUMP) $ 5.80
  • binance-bridged-usdc-bnb-smart-chainBinance Bridged USDC (BNB Smart Chain) (USDC) $ 0.999451
  • bonkBonk (BONK) $ 0.000014
  • solv-btcSolv Protocol BTC (SOLVBTC) $ 105,796.00
  • jupiter-exchange-solanaJupiter (JUP) $ 0.333968
  • filecoinFilecoin (FIL) $ 1.45
  • first-digital-usdFirst Digital USD (FDUSD) $ 0.998858
  • xdce-crowd-saleXDC Network (XDC) $ 0.056442
  • immutable-xImmutable (IMX) $ 0.495070
  • pancakeswap-tokenPancakeSwap (CAKE) $ 2.79
  • mantle-staked-etherMantle Staked Ether (METH) $ 4,089.06
  • global-dollarGlobal Dollar (USDG) $ 0.999966
  • spx6900SPX6900 (SPX) $ 0.998108
  • jupiter-staked-solJupiter Staked SOL (JUPSOL) $ 208.08
  • morphoMorpho (MORPHO) $ 1.68
  • fasttokenFasttoken (FTN) $ 2.01
  • arbitrum-bridged-wbtc-arbitrum-oneArbitrum Bridged WBTC (Arbitrum One) (WBTC) $ 105,961.00
  • ripple-usdRipple USD (RLUSD) $ 0.999788
  • celestiaCelestia (TIA) $ 1.01
  • clbtcclBTC (CLBTC) $ 106,349.00
  • doublezeroDoubleZero (2Z) $ 0.234585
  • injective-protocolInjective (INJ) $ 8.20
  • ousgOUSG (OUSG) $ 112.95
  • lido-daoLido DAO (LDO) $ 0.874791
  • blockstackStacks (STX) $ 0.421333
  • msolMarinade Staked SOL (MSOL) $ 241.87
  • optimismOptimism (OP) $ 0.419370
  • curve-dao-tokenCurve DAO (CRV) $ 0.525682
  • plasmaPlasma (XPL) $ 0.404720
  • cgeth-hashkey-cloudcgETH Hashkey Cloud (CGETH.HASH) $ 3,575.23
  • rna-2RNA (SN117) $ 4,708.96
  • fetch-aiArtificial Superintelligence Alliance (FET) $ 0.270015
  • l2-standard-bridged-weth-baseL2 Standard Bridged WETH (Base) (WETH) $ 3,806.93
  • ondo-us-dollar-yieldOndo US Dollar Yield (USDY) $ 1.11
  • superstate-short-duration-us-government-securities-fund-ustbSuperstate Short Duration U.S. Government Securities Fund (USTB) (USTB) $ 10.86
  • usdx-money-usdxStables Labs USDX (USDX) $ 0.994881
  • aerodrome-financeAerodrome Finance (AERO) $ 0.742769
  • the-graphThe Graph (GRT) $ 0.062687
  • sonic-3Sonic (S) $ 0.171284
  • pyth-networkPyth Network (PYTH) $ 0.109322
  • flokiFLOKI (FLOKI) $ 0.000065
  • tbtctBTC (TBTC) $ 105,821.00
  • arbitrum-bridged-weth-arbitrum-oneArbitrum Bridged WETH (Arbitrum One) (WETH) $ 3,804.65
  • tezosTezos (XTZ) $ 0.578503
  • saros-financeSaros (SAROS) $ 0.233881
  • ether-fiEther.fi (ETHFI) $ 1.08
  • kaiaKaia (KAIA) $ 0.103040
  • beldexBeldex (BDX) $ 0.079918
  • usdaiUSDai (USDAI) $ 1.02
  • newton-projectAB (AB) $ 0.007129
  • stader-ethxStader ETHx (ETHX) $ 4,076.05
  • gtethGTETH (GTETH) $ 3,794.24
  • myx-financeMYX Finance (MYX) $ 2.92
  • iotaIOTA (IOTA) $ 0.136321
  • conflux-tokenConflux (CFX) $ 0.106777
  • usual-usdUsual USD (USD0) $ 0.998227
  • trust-wallet-tokenTrust Wallet (TWT) $ 1.28
  • pendlePendle (PENDLE) $ 3.09
  • dashDash (DASH) $ 42.19
  • theta-tokenTheta Network (THETA) $ 0.523395
  • coinbase-wrapped-staked-ethCoinbase Wrapped Staked ETH (CBETH) $ 4,177.88
  • havvenSynthetix (SNX) $ 1.49
  • mantle-bridged-usdt-mantleMantle Bridged USDT (Mantle) (USDT) $ 1.00
  • usddUSDD (USDD) $ 1.00
  • polygon-pos-bridged-dai-polygon-posPolygon PoS Bridged DAI (Polygon POS) (DAI) $ 0.999908
  • swethSwell Ethereum (SWETH) $ 4,184.74
  • ethereum-name-serviceEthereum Name Service (ENS) $ 15.16
  • dogwifcoindogwifhat (WIF) $ 0.500468
  • true-usdTrueUSD (TUSD) $ 0.997824
  • bitcoin-avalanche-bridged-btc-bAvalanche Bridged BTC (Avalanche) (BTC.B) $ 105,921.00
  • galaGALA (GALA) $ 0.010611
  • the-sandboxThe Sandbox (SAND) $ 0.200256
  • virtual-protocolVirtuals Protocol (VIRTUAL) $ 0.745255
  • starknetStarknet (STRK) $ 0.112614
  • bittorrentBitTorrent (BTT) $ 0.00000049
  • bridged-usdc-polygon-pos-bridgePolygon Bridged USDC (Polygon PoS) (USDC.E) $ 0.999895
  • steakhouse-usdc-morpho-vaultSteakhouse USDC Morpho Vault (STEAKUSDC) $ 1.10
  • jasmycoinJasmyCoin (JASMY) $ 0.009787
  • benqi-liquid-staked-avaxBENQI Liquid Staked AVAX (SAVAX) $ 24.43
  • binance-peg-dogecoinBinance-Peg Dogecoin (DOGE) $ 0.183456
  • mantle-restaked-ethMantle Restaked ETH (CMETH) $ 4,099.54
  • jito-governance-tokenJito (JTO) $ 1.19
  • raydiumRaydium (RAY) $ 1.72
  • swissborgSwissBorg (BORG) $ 0.471084
  • zoraZora (ZORA) $ 0.100703
  • arbitrum-bridged-wrapped-eethArbitrum Bridged Wrapped eETH (Arbitrum) (WEETH) $ 4,098.50
  • vaultaVaulta (A) $ 0.281061
  • ether-fi-staked-ethether.fi Staked ETH (EETH) $ 3,799.52
  • eigenlayerEigenCloud (prev. EigenLayer) (EIGEN) $ 1.15
  • decentralandDecentraland (MANA) $ 0.228442
  • astherus-staked-bnbAster Staked BNB (ASBNB) $ 1,128.27
  • flowFlow (FLOW) $ 0.268824
  • sun-tokenSun Token (SUN) $ 0.022660
  • aethirAethir (ATH) $ 0.030039
  • syrupMaple Finance (SYRUP) $ 0.379354
  • bitcoin-svBitcoin SV (BSV) $ 20.86
  • hashnote-usycCircle USYC (USYC) $ 1.10
  • polygon-pos-bridged-weth-polygon-posPolygon PoS Bridged WETH (Polygon POS) (WETH) $ 3,798.63
  • frax-etherFrax Ether (FRXETH) $ 3,771.76
  • zero-gravity0G (0G) $ 1.90

North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign

0 1

North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign

North Korea-linked threat actors are escalating their cyber operations using decentralized and evasive malware tools, according to new findings from Cisco Talos and Google Threat Intelligence Group.

The campaigns aim to steal cryptocurrency, infiltrate networks, and evade detection through sophisticated job recruitment scams.

Evolving Malware Techniques Reflect Expanding Capabilities

Cisco Talos researchers identified an ongoing campaign by the North Korean group Famous Chollima. The group has used two complementary malware strains, BeaverTail and OtterCookie. These programs, traditionally used for credential theft and data exfiltration, have now evolved to integrate new functionalities and closer interoperation.

In a recent incident involving an organization in Sri Lanka, attackers lured a job seeker into installing malicious code disguised as part of a technical evaluation. Even though the organization itself was not a direct target, Cisco Talos analysts also observed a keylogging and screenshotting module linked to OtterCookie, which highlights the broader risk to individuals involved in fake job offers. This module covertly recorded keystrokes and captured desktop images, automatically transmitting them to a remote command server.

Cisco Talos reports that the North Korean group Famous Chollima is using a new JavaScript module combining BeaverTail and OtterCookie for keylogging and screenshots, targeting job seekers through fake offers and malicious Node.js packages. #CyberSecurity https://t.co/vRba8a3GcT

— Cyber_OSINT (@Cyber_O51NT) October 16, 2025

This observation underscores the ongoing evolution of North Korea-aligned threat groups and their focus on social engineering techniques to compromise unsuspecting targets.

Blockchain Used as a Command Infrastructure

Google’s Threat Intelligence Group (GTIG) identified an operation by a North Korea-linked actor, UNC5342. The group used a new malware called EtherHiding. This tool hides malicious JavaScript payloads on a public blockchain, turning it into a decentralized command and control (C2) network.

By using blockchain, attackers can change malware behavior remotely without traditional servers. Law enforcement takedowns become much harder. Furthermore, GTIG reported that UNC5342 applied EtherHiding in a social engineering campaign called Contagious Interview, which had been previously identified by Palo Alto Networks, demonstrating the persistence of North Korea-aligned threat actors.

What is EtherHiding?
It’s a novel technique where the attackers embed malicious payloads (like JADESNOW and INVISIBLEFERRET malware) within smart contracts on public blockchains (like BNB Smart Chain and Ethereum). https://t.co/AyKeSuPyWW pic.twitter.com/we4NV2PTu5

— blackorbird (@blackorbird) October 16, 2025

Targeting Job Seekers to Steal Cryptocurrency and Data

According to Google researchers, these cyber operations typically begin with fraudulent job postings aimed at professionals in the cryptocurrency and cybersecurity industries. Victims are invited to participate in fake assessments, during which they are instructed to download files embedded with malicious code.

The infection process often involves multiple malware families, including JadeSnow, BeaverTail, and InvisibleFerret. Together, they let attackers access systems, steal credentials, and deploy ransomware efficiently. The end goals range from espionage and financial theft to long-term network infiltration.

Cisco and Google have published indicators of compromise (IOCs) to help organizations detect and respond to ongoing North Korea-linked cyber threats. These resources provide technical details for identifying malicious activity and mitigating potential breaches. Researchers warn that the integration of blockchain and modular malware will likely continue to complicate global cybersecurity defense efforts.

The post North Korean Hackers Deploy Blockchain-Based Tools in Expanding Global Cyber Campaign appeared first on BeInCrypto.

Source

Leave A Reply

Your email address will not be published.